Author: Satyam Dubey
Collage: Symbiosis Law School (SLS), Nagpur
To the Point
The role of artificial intelligence (AI) is shifting from experimental business tool to a part of the day-to-day business decision making process. AI is employed in the hiring process, to track transactions, to analyze contracts, to identify fraud, to respond to customers, to create policies, and to uncover likely regulatory violations, among other applications. The issue of whether AI can undertake compliance-related tasks is no longer a matter of “if” but “how. The debate is not if but how can AI be used to undertake compliance related tasks. The more complicated issue is if an AI system itself is legally liable for failing to comply. The current legal landscape is even more in favour of no, as AI is unlikely to be an accountable decision-maker in front of a regulator, as a fiduciary, or as a holder of a statutory office. The obligation for legal responsibility remains with the corporation and also identifiable natural persons or other legal entity recognized. The more realistic model is thus ‘AI-assisted compliance’: AI can monitor, predict, flag and suggest, and there is a human governance structure that has authority, oversight and accountability. This distinction will be very relevant in 2026. The European Union (EU) has now implemented key features of the AI Act, such as transparency requirements and those concerning general-purpose AI, which will come in effect on 2 August 2026. The risk-based regime also explicitly calls for human intervention in systems that pose a high risk and obligations for monitoring, record keeping and competent oversight and incident escalation are placed on deployers. In India, the Digital Personal Data Protection Rules, 2025 were notified in November 2025 and have introduced a 2-8 phased framework for enforcement of the rules, highlighting the importance of organizations exercising control over the processing of personal data using automated methods.
Use of Legal Jargon
The main principle that is applied is accountability. Accountability is a duty-holder who can be identified in the context of corporate compliance, when a system causes or contributes to harm.
This relates to the concepts of vicarious liability, negligence, due diligence, statutory compliance, corporate attribution and governance and risk management of the board. There are problems of causation and foreseeability that arise from AI. A company can claim that an unexpected output came from a separate model (that of a third party) that was operating independently. This is no reason to break off liability. If the organization had chosen the system, they both had to define the use-case and provided the data, they had to incorporate the output into a business process – and if they didn’t provide reasonable safeguards, then a regulator or court could question whether the damage caused was foreseeable and preventable. Human in the loop governance is another concept that is important. The EU AI Act introduces a human-oversight framework, which obliges a natural person who is tasked with exercising oversight of high-risk AI to have adequate competence, training, authority and support. Oversight is not just a formal “signature”, but should be a way to grasp restrictions, identify anomalies, avoid being seduced by “automation bias”, and/or override and/or reverse the system’s output, when needed. This is a parallel line of risk, as data protection and confidentiality are a concern. Employee records, customer data, privileged communications, transaction data, commercially sensitive documents are examples of data AI compliance tools can ingest. The DPDP Act and Rules require the governance of purposeful and secure processing of digital personal data to be one of the growing concerns in India. This means that an AI compliance officer cannot be regarded as a “black box” into which sensitive information could be fed without restrictions
The Proof
The insights gained from the courts and regulators is that automated systems cannot take the place of organization responsibility and that governance is more important. The potentially most important lesson is that the legal system does not consider the technology a moral or legal entity itself, but instead the conduct of the organization around the technology. The National Institute of Standards and Technology’s AI Risk Management Framework defines trustworthy AI as having various characteristics, such as: Validity and reliability, Safety, Security and resilience, Accountability and transparency, Explainability and interpretability, Privacy enhancement, and Fairness with harmful bias managed. The National Institute of Standards and Technology’s AI Risk Management Framework characterizes trustworthy AI in the following ways:
Validity and reliability, Safety, Security and resilience, Accountability and transparency,
Explainability and interpretability, Privacy enhancement, and Fairness with harmful bias managed.
It introduces new risk-management practices for generative systems to its 2024 Generative AI Profile. In addition to focusing on the AI system, NIST emphasizes the accountability and specific roles and responsibilities of the organization, rather than on the AI system itself.
Second, the EU AI Act offers a real model for regulating AI. For high-risk AI systems, a qualitymanagement system as well as documentation, logs and conformity procedures are required. Competent human oversight, monitor operation, maintain log and report serious incidents are responsibilities of the deployer. The tasks are not particularly suited for an AI system to be the only legal responsible compliance officer: the statute explicitly assigns the tasks to humancontrolled organizations and defined persons.
Third, with the emerging jurisprudence, how common law principles can be brought to bear on AI outputs. In Moffatt v Air Canada, 2024 BCCRT 149, a Canadian tribunal ruled that Air Canada was liable for a mistake made by its web-based chatbot to a customer with regards to bereavement fares. The mistake made by the chatbot wasn’t considered a breach of any laws by the bot itself, but rather by the website’s owner.
Fourth, in Mata v Avianca, Inc., 22-cv-01461 (S.D.N.Y. 2023), attorneys filed court papers by utilizing the court’s AI tools that included bogus authorities created by ChatGPT. Fourth, in Mata v Avianca, Inc., 22-cv-01461 (S.D.N.Y. 2023), the attorneys entered court papers using the court’s artificial intelligence tools, including bogus authorities generated by ChatGPT. The court handed down a $5,000 fine, and reiterated that attorneys are still accountable for the accuracy of what they represent to the court, regardless of the use of technology in research and writing.
Finally, State v Loomis, 881 N.W.2d 749 (Wis. In consideration of the use of the COMPAS riskassessment tool at sentencing, they took into account a 2016 report by the Inspectorate (2016). The Wisconsin Supreme Court had no intention of banning the tool’s use, but highlighted restrictions and warnings about the tool’s use in the judicial process. The case represents a larger point about corporate compliance – predictive systems can be a factor to consider, but the findings of such systems should not be considered foolproof and self-evident answers to legal questions.
AI Hallucination and the Need for Verification.
The issue with generative AI is the one it presents that is both plausible yet false: compliance. A system can create and make up authorities, incorrectly state a rule, assign a rule to a different authority or inaccurately summarize a policy. This can be an extra risk in a compliance world if one output error is made, it can be copied to a policy, investigation memo, board paper or regulatory filing. The verification duty should thus be based upon risk. Generally, legal opinions, regulatory submissions, suspicious-transaction determinations, and sanctions decisions and employee-disciplinary recommendations should be subject to documented human verification, while low-risk drafting may allow for some automated assistance with the work, provided that such assistance is limited by a process of review that is documented. The key question is, is the degree of scrutiny the organization used adequate, given the potential repercussions of a mistake? The auditability, Explainability and Evidentiary Record will be discussed
There is an evidentiary challenge in a further legal challenge. If a compliance alert results in an employee’s termination, or rejection of a customer, freezing of an account, disclosure to a regulator or an internal investigation, the organization may have to defend itself against the compliance alert and the reasons for the action in the future. That might be hard to do with an opaque model. These types of audit logs, version histories, source data records, prompts, model outputs and human overrides therefore are not just technically relevant but legal as well. They document the facts of an investigation, show reasonable precautions taken, and determine if a mistake was made due to poor data, model behaviour or faulty configuration/human usage. Explainability does not have to be complete mathematical information about a model, but certainly should be more than just an “explanation” of the basis, limits and source of a material compliance decision.
A Non-Delegable Duty is a duty that is not delegated
In many instances, the law governing corporations allows tasks to be delegated but not the responsibility. A board can assign a responsibility to an executive, which may then be assigned to software; however, the board can continue to have responsibility for data review at the principal decision maker level. This is the same principle with regard to AI. The responsibilities of the corporation with regard to algorithms do not automatically transfer to a vendor, cloud-based solution, or automatic updates. It is important therefore that a system is created that clearly separates delegated operational authority from non-delegated accountability. Each meaningful AI workflow must specify who will be responsible for the workflow, who will review it, an escalation path for it, and the actions that will be taken and what was relied upon.
Corporate Compliance Architecture
The issue of legal liability is more clearly understood if compliance is the architecture of governance and not just the job title of one. A typical compliance officer functions in a chain of command: The board sets the risk appetite, senior management put in place controls, the internal audit function tests this and the compliance function monitors and reports on adherence to the controls. An AI can perform any of these functions, but of course doesn’t have the institutional power to make these actions a legally significant part. May perform a control without being the legal owner of the control. It is significant for purposes of attribution since the company is accountable for the design, supervision, documentation and remediation of its compliance programme
Abstract
In this article, they’ll look at the possibility of AI being a legally responsible compliance officer in a corporation. It believes that AI can take on a role of significant compliance but that, at the moment, the human and corporate structures that are accountable by law cannot be replaced by AI. The analysis is centred around the accountability of the AI, human oversight, data governance, explainability, auditability and liability for AI-generated outputs. EU AI Act, Digital Personal Data Protection framework of India, NIST’s AI Risk Management Framework, and recently emerging case law with regard to AI-based decision tools and chatbots are compared. The article concludes that the model that is legally sustainable is not an autonomous machine officer; it’s a governed system of artificial intelligence that is under delegated authority, continuous supervision by humans, and has documented controls, and assigns responsibility.
Case Laws
There is a unified suggestion given by the authorities: the legal duty to take responsibility goes with the institution which deploys, manages or makes use of the technology. Moffatt shows how an organization should take responsibility for an AI’s output that is meant to be used by a customer; Mata explains that a professional user must still verify an AI’s output, even when the AI is used to help with verification; Loomis provides examples of the precautions needed when using opaque scoring tools that affect consequential decisions; and the emerging employment litigation shows how traditional discrimination law may apply to an AI’s output used in screening. There is no source of legal obligations on software in any of these authorities. As a result, the overall impact of their combined effect is doctrinal—and not just technological—that is, the principles of negligence, professional responsibility, discrimination, due process and corporate governance can continue to apply even if the means of decision-making is. algorithmic
The relative importance of the authorities
1. The case of Moffatt v Air Canada, 2024 BCCRT 149 (British Columbia Civil Resolution Tribunal), is another case in point. The chatbot was considered to be an Air Canada customerfacingtool and the company was responsible for the repercussions of inaccurate information. This goes to support the argument that a corporation can’t shrug off its duty simply by layering an AI between itself and the customer.
2. Mata v Avianca, Inc., No. 22-cv-01461 (PKC), Opinion and Order on Sanctions (S.D.N.Y. June 22, 2023). Counsels made use of generative AI for legal research, and added made-up case authorities to submissions. There were then sanctions imposed due to the fact the professional duties were still to be performed by the lawyers. It is a very applicable concept to compliance departments that leverage generative AI for legal analysis, regulatory reports or internal investigations.
3. State v Loomis, 881 N.W.2d 749 (Wis. 2016). The Wisconsin Supreme Court gave permission to consider a risk-assessment tool when sentencing, with a note of caution. Its decision illustrates the possibility of algorithmic tools as decision-support systems and some concerns about opaqueness and over-reliance on algorithms in the context of due process.
4. Mobley v Workday, Inc., No. 23-cv-00770-RFL (N.D. Cal.). The lawsuit is about claims of employment screening practices using AI discriminating against applicants based on protected characteristics. Orders issued in 2025 and 2026 have enabled the case to proceed through the certification and discovery and amended pleadings phase. The case illustrates that the deploying employer can become a conventional discrimination defendant because of the use of the AI in the hiring process even though it does not automatically become a defendant just because it made or influenced the screening recommendation.
Conclusion
What sounds like a ‘legally responsible compliance officer’ is a step too far for the state of the law at this time, but a very capable compliance instrument it can be, when it is based on AI. There is a general requirement in the law for an accountable person or organization for consequential decisions. Corporate governance, statutory duties, professional obligations, data-protection obligations and regulatory enforcement is all based on identifiable duty-holders, and not autonomous software. The right legal structure is thus a human controlled AI compliance role. An organization needs to specify the allowed use of the system; categorise the legal and operational risks associated with each use-case; manage access to personal and privileged information; validate the model and its results; keep logs and audit trails; test for bias and error; have an escalation process; and ensure that the system can be bypassed by an appropriate individual. Agreements with AI vendors should address the responsibilities for data privacy, audit rights, incident notification, service failures and security. AI can create a Policy, spot a suspicious transaction, review a contract to a Rulebook or forecast a compliance hotspot. It can even do these jobs without getting tired and at a larger scale than human. But it is not a final place of legal judgment when the decision has a significant impact on rights and duties or when the impact concerns regulated activities and/or significant corporate exposure. So, ‘AI replaces the compliance officer’ isn’t likely to be the future of compliance. This is a legal structure that is more defensible, “AI as an assistant to the compliance officer, with human and corporate responsibility remaining intact”
The authoritativeness and selection of sources.
• On 2 August, the European Commission will begin enforcing the rules of the AI Act and introduce transparency requirements.
• The Digital Personal Data Protection Rules, 2025 (notified 14 November 2025) are issued by the Ministry of Electronics and Information Technology, Government of India.
• Rules of the EU AI Act (current consolidated versions of Articles 14 and 26) (EU) 2024/1689 (EU AI Act), accessed on 20 September 2026.
• Digital Personal Data Protection Act, 2023, the Government of India, Digital Personal Data Protection Rules, 2025, Government of India.
• The National Institute of Standards and Technology (NIST) Risk Management Framework for Artificial Intelligence (AI RMF 1.0) (2023).
• The AI Risk Management Framework, Generative Artificial Intelligence Profile (AI 600-1), 2024 (Updated 2026), National Institute of Standards and Technology (NIST).
• Regulation (EU) 2024/1689, Articles 16, 19, 26 and related provisions.
• Moffatt v Air Canada, 2024 BCCRT 149 (CanLII).
• Mata v Avianca, Inc., No. 22-cv-01461 (PKC), Opinion and Order on Sanctions (S.D.N.Y.
June 22, 2023).
• State v Loomis, 881 N.W.2d 749 (Wis. 2016).
• Mobley v Workday, Inc., No. 23-cv-00770-RFL (N.D. Cal.), including orders dated 16 May 2025, 6 March 2026 and 1 July 2026.
